TOPIC

Tooling

SIEM, EDR, and the rest of the acronym soup: what the tools do, what they cost you in attention, and when you genuinely need them.

1 ARTICLE · 4 TERMS

Articles

Key terms

EDR

Endpoint Detection and Response: an agent that records endpoint activity, detects suspicious behavior, and lets responders isolate or remediate machines remotely.

Security Information and Event Management: a platform that collects and correlates logs across systems so analysts can detect and investigate incidents.

Security Orchestration, Automation and Response: a platform that runs codified playbooks against a triaged case, executing containment actions across systems and recording the trail.

XDR

Extended Detection and Response: correlates telemetry across one vendor's own sensors, typically endpoint, identity, email and network, and ships its detection content already written.